7.2
CVE-2021-1543
- EPSS 0.28%
- Published 16.06.2021 18:15:08
- Last modified 21.11.2024 05:44:35
- Source psirt@cisco.com
- Teams watchlist Login
- Open Login
Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root user on the underlying operating system Conduct a cross-site scripting (XSS) attack Conduct an HTML injection attack For more information about these vulnerabilities, see the Details section of this advisory.
Data is provided by the National Vulnerability Database (NVD)
Cisco ≫ Sf220-24 Firmware Version < 1.2.0.6
Cisco ≫ Sf220-24p Firmware Version < 1.2.0.6
Cisco ≫ Sf220-48 Firmware Version < 1.2.0.6
Cisco ≫ Sf220-48p Firmware Version < 1.2.0.6
Cisco ≫ Sg220-26 Firmware Version < 1.2.0.6
Cisco ≫ Sg220-26p Firmware Version < 1.2.0.6
Cisco ≫ Sg220-28mp Firmware Version < 1.2.0.6
Cisco ≫ Sg220-50 Firmware Version < 1.2.0.6
Cisco ≫ Sg220-50p Firmware Version < 1.2.0.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.28% | 0.507 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
psirt@cisco.com | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.